First published: Thu Feb 16 2023(Updated: )
A flaw was found in the HashiCorp go-getter package. Affected versions of the HashiCorp go-getter package are vulnerable to a denial of service via a malicious compressed archive.
Credit: security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp go-getter | <=1.6.2 | |
HashiCorp go-getter | =2.1.1 | |
redhat/go-getter | <1.7.0 | 1.7.0 |
redhat/go-getter | <2.2.0 | 2.2.0 |
go/github.com/hashicorp/go-getter/v2 | >=2.0.0<2.2.0 | 2.2.0 |
go/github.com/hashicorp/go-getter | <1.7.0 | 1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-0475.
The severity of CVE-2023-0475 is medium with a CVSS score of 6.5.
CVE-2023-0475 is a denial of service vulnerability and cannot be directly exploited for remote code execution or privilege escalation.
The affected versions of the HashiCorp go-getter package are up to exclusive 1.6.2 and 2.1.1.
To fix CVE-2023-0475, update to version 1.7.0 or higher for the HashiCorp go-getter package.